Connect with us

Financial

LATEST CYBERSECURITY CHALLENGES IN THE WORLD OF BFSI

Published

on

Exclusive interview with Premchand Kurup, CEO, Paramount

Which emerging cyber risks are most likely to influence or reshape GCC banking regulations in the coming years?

We live in an era where nearly every banking service depends on advanced digital infrastructure, and cybercriminals are aware of it. With the emergence of AI, the risks have evolved even further, enabling attacks that can adapt and operate at an unprecedented scale. Over the period of 2024–2026, GCC banking regulations in the region are being influenced by the convergence of advanced ransomware, API-driven open banking risks and AI-enabled cyber threats.

Firstly, targeted ransomware and data extortion attacks against banks and fintechs in the Gulf region have evolved from isolated incidents into a persistent and systemic risk. Financial institutions in the UAE and across the GCC region have experienced a noticeable rise in incidents and malware activity through 2024 and into 2025 by nearly 100%, and this is specific to Paramount. . In response, regulators are tightening requirements for incident reporting timelines, operational resilience testing and recovery capabilities within central banks and national cybersecurity frameworks, with these requirements expected to become more stringent in 2026.

Secondly, the rapid expansion of open banking and digital transformation initiatives has made API security and cloud exposure critical regulatory concerns. Misconfigured cloud environments, weak API authentication, and complex third-party integrations are creating new attack surfaces that traditional perimeter-based security models cannot adequately protect. As a result, regulators in the UAE, Saudi Arabia, and other GCC countries are strengthening supervisory expectations around identity management, data protection and third-party risk management within banking regulations.

Additionally, the rise of AI-driven fraud and AI-assisted cyberattacks is reshaping how supervisors view the intersection of model risks and cyber risks. AI is being increasingly used to support credit assessment, KYC and fraud detection, while also being leveraged by attackers to scale phishing, social engineering and evasion techniques. This dual-use nature of AI is prompting regulators to develop guidance on AI governance, explainability and enhanced monitoring of AI-enabled processes in the financial sector.

What is one underrated cybersecurity innovation today that you believe will become critical for the Middle East’s BFSI sector over the next few years?

One of the most underrated cybersecurity innovations today, and yet one that is likely to become critical for the Middle East’s banking, financial services and insurance (BFSI) sector over the next few years, is behaviour-based analytics, which has become deeply integrated into security operations centre (SOC) functions and fraud detection systems. Numerous financial institutions still rely heavily on static, rule-based systems that trigger alerts based on fixed thresholds or known attack signatures. While effective against traditional threats, these approaches struggle to detect modern attacks that rely on lateral movement, living off the land (LOTL) techniques and sophisticated social engineering.

In contrast, behaviour-driven analytics establishs dynamic baselines for users, devices, applications and APIs. It continuously monitors the way accounts are accessed, transactions are executed and systems communicate, enabling early detection of anomalies that signal potential fraud or intrusion. These capabilities closely mirror the patterns observed in recent high-impact attacks on banks and fintechs across the region. For GCC banks navigating rapid cloud adoption, open banking frameworks and increasing use of AI in core operations, behavioural analytics is becoming essential. It allows institutions to distinguish legitimate high-volume digital activity from subtle intrusions, as highlighted in the report titled ‘2025 Global Digital Trust Insights – Middle East findings’.

Reflecting this shift, Paramount’s advisory and SOC services in the region are increasingly promoting a transition from purely rule-driven monitoring to a blended model that combines behavioural analytics, traditional rules, and threat intelligence. This integrated approach significantly improves detection speed and reduces false positives in complex Middle Eastern financial environments.

From the Paramount SOC’s perspective, approximately how many security incidents or threats have been monitored and mitigated this year


Over the last year we have issued over 592 critical advisories and mitigated them. Critical advisories are those that have the potential to halt business operations significantly.
The year 2026 has just begun, and we have issued nearly 100 advisories already.

Apart from critical advisories we have issued regular 318 advisories this year while the number stood at 2208 last year . We have just begun the year, but the number of alerts shows an increasing trend.

What types of cyber threats are most frequently detected and addressed by the SOC?

During the fiscal year 2024–2025, the most frequently detected threats identified by Paramount’s SOC include phishing and credential theft leading to account takeover, often using highly localised and AI-generated lures. SOC teams also regularly respond to ransomware and data extortion campaigns, alongside API, web application, and DDoS attacks targeting digital banking platforms. Moreover, cloud misconfigurations and excessive access permissions remain a persistent risk, frequently identified through continuous monitoring and threat hunting.

How can C-suite leaders better prepare their organisations, and what proactive steps should banks take to stay ahead of fraud and cyber threats?

For banks across the GCC region, C-suite leaders need to treat cyber resilience as a core board-level business capability, and not simply as a technical or IT function. With cyber threats having direct implications for financial stability, reputation, and regulatory compliance, leadership should embed cyber risk into enterprise risk management frameworks and board reporting. Major threat scenarios such as prolonged digital channel outages, data extortion incidents, or systemic third-party failures should be quantified and reviewed alongside credit and liquidity risks, in line with evolving GCC regulatory expectations. Leaders should further align their cyber strategies with national cybersecurity frameworks and central bank guidance, using independent maturity assessments to identify gaps and prioritise investments through 2026.

From an operational and technology perspective, adopting a zero-trust approach across identities, devices, networks and applications is becoming essential, particularly in API-enabled and cloud-based banking environments. This should be supported by strong SOC and incident response capabilities, whether in-house or through specialised providers such as Paramount, to ensure 24/7 monitoring, rapid containment and documented playbooks for both regulators and customers. Banks also need to invest in advanced fraud analytics and behaviour-based monitoring to detect account takeover and payment fraud, particularly as AI tools make phishing and social engineering more convincing, as witnessed in recent UAE ransomware trends.

Equally important is rigorous third-party and supply chain risk management. This includes structured security due diligence and continuous monitoring of fintech partners, cloud providers and critical vendors, given the growing risk of indirect compromised paths into Gulf financial institutions. Finally, C-suite leaders should actively promote a strong cyber resilience culture. This involves running realistic simulations of ransomware, data leaks, and payment fraud scenarios to sharpen organisational readiness and showcase proactive resilience to regulators, customers and shareholders.

Given the distinct regulatory, cultural, and operational landscape of the GCC, what makes cybersecurity in the region’s BFSI sector uniquely challenging compared to the US or Europe?

Cybersecurity in the GCC region’s BFSI sector is uniquely challenging because financial institutions operate at the intersection of rapid digital transformation, high geopolitical relevance and complex, multi-layered regulation. From a regulatory standpoint, institutions in the region must comply simultaneously with national cybersecurity authorities, central banks, and in some cases, free zone regulators. These entities impose detailed requirements on controls, data protection and incident reporting, creating a more fragmented and demanding compliance landscape than in many single-jurisdiction markets. The situation is further complicated by strict data residency and data sovereignty rules, which significantly influence how banks can design and deploy cloud, analytics, and cross-border platforms.

Operationally, GCC banks are advancing quickly into digital, mobile and open banking services, often faster than ecosystem-wide security maturity. While this supports financial inclusion, it also expands the attack surface through APIs, cloud services, and fintech partnerships. At the same time, the Gulf region has become one of the most actively targeted regions for financially motivated cybercrime and disruptive attacks, with banks and fintechs featuring prominently in 2024–2025 reports on ransomware, DDoS campaigns and sophisticated fraud schemes. The combination of rapid innovation, partner security, high attacker interest and evolving regulatory expectations creates a risk profile that is distinct from more established markets in North America and Europe.

In response, Paramount’s work with GCC BFSI clients focuses on developing region-specific security architectures and systems rather than simply importing models from other geographies. This includes designing frameworks aligned with local regulatory obligations, regional threat intelligence and the operational realities of Middle Eastern institutions as they evolve through 2026.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Financial

Navigating Growth and Liquidity: The Shift to Predictive Credit Intelligence in the GCC

Published

on

As GCC businesses expand into new markets and increasingly complex supply chains, traditional credit assessment is giving way to a more predictive approach. In this interview with Mohamad Jomaa, CEO and Country Manager for GCC and Egypt at Coface, we explore how real-time data, AI and early-warning intelligence are helping CFOs anticipate payment risk, protect working capital and make more confident decisions across customers, suppliers and markets.

What is driving the shift from relationship-based credit decisions to predictive credit intelligence among CFOs in the GCC?

Relationships remain fundamental to business in the GCC and will continue to be. What has changed is the speed at which companies are expanding into new sectors, markets, and supply chains. As organizations grow beyond their traditional networks, finance leaders need additional tools to assess customers, suppliers, and partners they may not know well.

Today’s CFOs are increasingly complementing business relationships with data-driven insights. They need greater visibility not only into credit risk, but also into supply chain dependencies, corporate ownership structures, payment behavior, and potential vulnerabilities across their ecosystem.

Predictive intelligence provides that forward-looking perspective. It helps businesses make faster and more informed decisions, strengthen due diligence processes, identify opportunities, and anticipate risks before they impact cash flow, operations, or growth plans.

What trends are you currently seeing in payment delays and corporate defaults across the UAE and Saudi Arabia?

The overall economic outlook in both the UAE and Saudi Arabia remains positive, supported by ambitious investment programs and continued economic diversification. At the same time, businesses continue to face uneven market conditions across sectors.

Drawing on Coface’s unique experience as a global trade credit insurer, we monitor payment behavior, claims activity, and credit events across millions of companies worldwide. What we are seeing today is not necessarily a significant increase in corporate failures, but rather signs of pressure on working capital in specific industries.

Payment delays have become more common in sectors exposed to longer project cycles, margin pressure, or supply chain disruptions. For finance leaders, the challenge is distinguishing between temporary liquidity constraints and deteriorating credit quality. This is where access to real-time payment data and early warning indicators becomes particularly valuable.

How can better credit intelligence improve cash flow, working capital, and overall financial resilience?

Better intelligence enables businesses to make more informed decisions across the entire customer and supplier lifecycle. By combining financial information, payment behavior, sector analysis, ownership data, Country Risk Assessments, Sector Risk Assessments, and ongoing monitoring, organizations gain a much clearer view of both risk and opportunity.

This has a direct impact on cash flow and working capital. Businesses can identify signs of financial stress earlier, reduce exposure to overdue accounts, prioritize collections efforts, and allocate credit more effectively. Access to real-time information and early warning indicators allows companies to act before issues translate into cash flow challenges.

Increasingly, however, financial resilience is not only about customer risk. It is also about understanding vulnerabilities across the supply chain. A disruption involving a key supplier, contractor, or logistics partner can have a significant impact on operations, costs, and liquidity. Better intelligence provides greater visibility into these critical dependencies, helping organizations identify concentration risks, assess the financial health of strategic partners, and strengthen business continuity planning.

As companies expand into new markets and engage with new customers, suppliers, and partners, they need confidence in who they are doing business with. Access to reliable data on ownership structures, financial health, payment behavior, sector outlooks, and country risk helps organizations make better-informed decisions and reduce uncertainty when entering new commercial relationships.

. What warning signs should finance leaders monitor before extending credit to new customers or entering unfamiliar markets?

Financial statements remain important, but they only tell part of the story. Finance leaders should also evaluate payment behavior, ownership structures, management stability, sector outlooks, supplier concentration, and exposure to geopolitical or regulatory risks.

One of the most valuable early warning indicators is a deterioration in payment behavior. In many cases, companies begin showing signs of financial stress long before it becomes visible in published financial statements.

Similarly, supply chain concentration risks should not be overlooked. A business may appear financially sound while remaining highly dependent on a small number of customers, suppliers, or projects. Understanding these dependencies is an increasingly important component of due diligence.

Effective credit decisions require a broader assessment of the business ecosystem rather than focusing solely on traditional financial metrics.

This is why a combination of company information, payment behavior, Country Risk Assessments, Sector Risk Assessments, and supply chain intelligence is increasingly becoming an essential part of the decision-making process.

How are AI and predictive analytics changing the way organizations assess credit risk and make financing decisions?

Financial statements remain important, but they only tell part of the story. Finance leaders should also evaluate payment behavior, ownership structures, management stability, sector outlooks, supplier concentration, and exposure to geopolitical or regulatory risks.

One of the most valuable early warning indicators is a deterioration in payment behavior. In many cases, companies begin showing signs of financial stress long before it becomes visible in published financial statements.

Similarly, supply chain concentration risks should not be overlooked. A business may appear financially sound while remaining highly dependent on a small number of customers, suppliers, or projects. Understanding these dependencies is an increasingly important component of due diligence.

Effective credit decisions require a broader assessment of the business ecosystem rather than focusing solely on traditional financial metrics.

This is why a combination of company information, payment behavior, Country Risk Assessments, Sector Risk Assessments, and supply chain intelligence is increasingly becoming an essential part of the decision-making process.

What sectors in the GCC are showing the strongest opportunities, and where are the highest risks based on your data?

Our outlook combines insights from Coface’s payment experience data, claims observations, Country Risk Assessments and Sector Risk Assessments. Together, these provide a comprehensive view of the opportunities and vulnerabilities shaping the business environment across the GCC.

We continue to see attractive opportunities in sectors supported by economic diversification strategies, digital transformation, infrastructure investment, logistics development and the energy transition. These areas are benefiting from sustained investment, strong policy support and growing regional demand.

At the same time, businesses operating in sectors facing tighter margins, elevated input costs, project execution challenges or longer payment cycles require closer monitoring. What is important to remember is that risk is rarely uniform across an entire sector. Performance can vary significantly from one company to another depending on its financial strength, competitive positioning, customer base and exposure to broader supply chain dynamics.

Looking ahead, how do you see the role of predictive intelligence evolving within corporate finance over the next three to five years?

Over the next three to five years, predictive intelligence will become an integral component of decision-making across finance, procurement, sales, treasury, compliance, and risk management functions.

We expect companies to move beyond using intelligence solely for credit assessments and begin embedding it throughout the business. This includes supplier selection, customer onboarding, supply chain management, compliance checks, investment decisions, and strategic planning.

The organizations that will be most successful are those that can combine technology, data, and human expertise to obtain a holistic understanding of their business ecosystem.

In an increasingly interconnected world, success will depend not only on knowing who you do business with, but also on understanding the risks and opportunities across the entire value chain. Access to reliable, forward-looking intelligence will therefore become a key competitive advantage, helping companies grow confidently while remaining resilient in a rapidly changing environment.

Continue Reading

Financial

Standard Chartered becomes first Global Systemically Important Bank (G-SIB) to launch Institutional Bitcoin and Ether spot trading in the UAE

Published

on

Standard Chartered today announced the expansion of its institutional Bitcoin (BTC/USD) and Ether (ETH/USD) spot trading in the UAE through ‘Standard Chartered DIFC’[1].

This makes Standard Chartered the first Global Systemically Important Bank (G-SIB) to offer the capability in the market and the only global bank currently offering institutional digital asset spot trading in the region. The move further broadens the bank’s regulated digital asset offering in the UAE by adding execution to its custody offering.

The capability enables eligible institutional clients to access deliverable Bitcoin and Ether spot trading through Standard Chartered’s electronic trading channels. It is integrated into the Bank’s existing platforms, enabling clients to access crypto-asset trading through familiar FX interfaces.

Clients may settle trades with a custodian of their choice, including Standard Chartered’s digital asset custody solution that was launched in September 2024.

Rola Abu Manneh, Chief Executive Officer, UAE, Middle East and Pakistan at Standard Chartered, said: “The UAE has developed a clear digital assets regulatory framework that supports institutional participation and innovation. Extending our Bitcoin and Ether spot trading capability to institutional clients is a significant step in broadening our regulated digital asset proposition in the market. By combining execution with secure custody, governance and the connectivity of a global bank, we are providing clients with a more integrated way to participate in digital asset markets.”

Christopher Parsons, Senior Executive Officer, Standard Chartered DIFC, said: “DIFC provides an established platform for international financial institutions to deploy global capabilities across markets. Extending our institutional digital asset trading capability through the Centre demonstrates the strength of that model, combining Standard Chartered’s global markets expertise and network with a regulated base from which we can serve clients across the region.”

Standard Chartered first introduced institutional Bitcoin and Ether spot trading through its UK branch in July 2025, becoming the first G-SIB to offer deliverable spot crypto-asset trading to institutional clients. The UAE launch extends that established global capability into a market where the Bank has been building its institutional grade digital assets offering.

The latest UAE capability builds on Standard Chartered’s broader digital assets strategy, which spans custody, trading and tokenisation capabilities through its Corporate and Investment Bank, while its ventures ecosystem extends these capabilities through Zodia Markets and Libeara. Together, these capabilities are designed to support institutional clients’ evolving digital asset needs through regulated infrastructure and services.

Continue Reading

Financial

Dhruva to Rebrand as Ryan Across the Middle East, Signaling Unified Global Brand

Published

on

Dhruva will adopt the Ryan brand across the UAE and Saudi Arabia by the end of 2026, uniting the practice with Ryan’s global identity and international platform.

Dhruva, a leading tax consultancy firm in the Middle East, and Ryan, a leading global tax services and software provider, today announced that Dhruva will transition to the Ryan brand across the United Arab Emirates (UAE) and the Kingdom of Saudi Arabia. The rebranding will be completed by the end of 2026, bringing the practice under Ryan’s global identity and reinforcing its position as part of the world’s leading global-scale specialist in business tax.

The transition marks the next phase of the strategic joint venture announced in 2025 and reflects the continued integration of Dhruva’s regional capabilities with Ryan’s global platform, technology, and international resources. Clients across the Middle East will continue to benefit from the same trusted advisory teams, enhanced by access to Ryan’s worldwide expertise and service capabilities.


“The Middle East has been a strategic growth market for us for many years, and we have built a strong advisory practice founded on deep client relationships, technical excellence, and local market understanding,” said Dinesh Kanabar, Founder, Chairman, and CEO, Dhruva Advisors and Vice Chairman, Ryan.

“The transition to the Ryan brand marks a significant milestone in our journey and reflects the strength of our partnership. By combining our regional expertise with Ryan’s global scale, technology, and international capabilities, we are creating an even stronger platform to support clients across the region as they navigate an increasingly dynamic and evolving tax landscape.”


“The Middle East is one of the most important growth markets for tax advisory services globally, and we are investing in the region with a long-term view,” said Tom Shave, President of Ryan’s European and Asia-Pacific Operations. “Uniting under the Ryan brand strengthens how we serve clients across the UAE, Saudi Arabia, and Europe—bringing seamless access to our global expertise, technology, and international resources through one trusted platform. This transition marks an important milestone in our integration and reinforces our commitment to the region’s future.”


Ryan will continue to invest in its Middle East operations, expanding its team, capabilities, and regional presence across key markets, including Dubai, Abu Dhabi, and Riyadh. The practice provides comprehensive tax advisory services spanning corporate tax, value-added tax (VAT) and indirect tax, transfer pricing, mergers and acquisitions (M&A) tax structuring, research and development (R&D), and cross-border compliance.


“The response from our clients over the past year has been the clearest validation of this partnership,” said Nimish Goel, Leader, Middle East, Dhruva, a Ryan Affiliate. “From the outset, our teams have been integrating Ryan’s global capabilities in technology, specialized expertise, and best practices into the work we already lead in the region. Adopting the Ryan brand is the natural next step. It is the same people and the same trusted relationships, now carrying the name of the largest Firm in the world dedicated exclusively to business taxes.”


The rebranding will be implemented in phases during the second half of 2026, with signage, visual identity, and digital properties transitioning to the Ryan brand across the region.

Continue Reading

Trending

Copyright © 2023 | The Integrator